Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-22120 — AI Deep Analysis Summary

CVSS 9.1 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Zabbix suffers from a **Time-Based Blind SQL Injection** due to unsanitized input in the `clientip` field within the Audit Log.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **CWE-20: Improper Input Validation**. The system fails to clean the `clientip` field before logging it into the audit database.…

Q3Who is affected? (Versions/Components)

📦 **Affected Versions**: • **Zabbix 6.0.0 - 6.0.27** • **Zabbix 6.4.0 - 6.4.12** • **Zabbix 7.0.0alpha1** ⚠️ If you run these versions, you are at risk!

Q4What can hackers do? (Privileges/Data)

💻 **Attacker Capabilities**: • **Full RCE**: Execute arbitrary commands on the server. • **Data Exfiltration**: Access sensitive monitoring data. • **Privilege Escalation**: Gain administrative control. 🔑 Requires a **l…

Q5Is exploitation threshold high? (Auth/Config)

🔐 **Exploitation Threshold**: • **Auth Required**: Yes, needs a valid session (low-privilege user). • **Config Required**: User must have permission to execute scripts. • **Network**: Remote exploitation possible (AV:N)…

Q6Is there a public Exp? (PoC/Wild Exploitation)

💣 **Public Exploits**: **YES**. Multiple PoCs are available on GitHub: • `CVE-2024-22120-RCE` (Time-based SQLi → RCE) • `CVE-2024-22120-RCE-with-gopher` (SSRF/XXE via Gopher) • Nuclei templates for automated scanning. 🔥 …

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: 1. **Scan**: Use Nuclei templates (`CVE-2024-22120.yaml`). 2. **Verify**: Check if your Zabbix version is in the affected list. 3.…

Q8Is it fixed officially? (Patch/Mitigation)

🩹 **Official Fix**: **YES**. Zabbix has acknowledged the issue (ZBX-24505). Users should **update immediately** to the latest patched version of Zabbix 6.0, 6.4, or 7.0.…

Q9What if no patch? (Workaround)

🛑 **No Patch Workaround**: 1. **Restrict Permissions**: Remove script execution rights from low-privilege users. 2. **Network Segmentation**: Limit access to the Zabbix server interface. 3.…

Q10Is it urgent? (Priority Suggestion)

🚨 **Urgency**: **CRITICAL (P1)**. • **CVSS Score**: High (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). • **Impact**: Full RCE. • **Availability**: Easy to exploit with public tools. ⏳ **Action**: Patch immediately or apply str…